Quantum key distribution using superposition of the vacuum and single photon states 
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B92-type and BB84-type quantum cryptography schemes using superposed states of the 
vacuum and single particle states which are robust against PNS attacks are studied. The 
number of securely transferred classical bits per particle (not per qubit) sent in these schemes 
is calculated and found to have upper bounds. Possible experimental realizations using the 
cavity QED or linear optics are suggested. 



I. INTRODUCTION 

Recent progress in theories and experiments 0, 0, 0, 0, 01 of generation and manipulation of single photons allows 
one to think the quantum information processing utilizing single particles feasible. The first commercial application of 
quantum information science at a single qubit level might be the quantum key distribution (QKD)Q. In the typical 
QKD scheme a sender (Alice) shares a secret key with a receiver(Bob) by sending superposition of photon polarization 
states. However, one can encode information not only in particle states but also in the vacuum as shown in some 
QKD schemes (mainly in double ray schemes) 0j B ■ In other words the vacuum can play a role of an information 
carrier as particles do. Two of authors had suggested the quantum teleportation and the Bell inequality test using 
single-particle entanglement which was verified experimentally later |lflj. In this direction we proposed|llj the Ekert- 
type Il2l single ray quantum cryptography scheme using the entangled states of the vacuum and the single particle 
state |lCl Im llil llil ll^ HI . ITol Eol . The main purpose of this work is to present a single ray B92-type and 
a BB84-type[2^ quantum cryptography schemes using superposed states of the vacuum and single photon states. In 
our schemes the detection of the superposition state is possible with cavity QED devices or linear optics devices and 
single photon detectors. Consider a quantum memory with the state \4>) = a|0) +/311) which is a superposition of the 
vacuum |0) and a single photon state |1) (optical qubit) which can be prepared by a photon source using parametric 
down conversion [l^ or linear opticS|2j| with the optical state truncation. By choosing small enough we can 
make the expected number of photons in |(/)) (i.e., |/3p) arbitrary small. It implies that we can encode classical bit 
information in the superposition of the vacuum and single photon state with \(3\ <C 1, which is very faint light. Does 
this also mean that the legitimate participants can share their secret key through a QKD protocol with an arbitrary 
faint light source to hide quantum channel itself from eavesdroppers? We show that the answer is no at least for 
straight forward generalizations of B92 and BB84-type QKD with the vacuum-photon superposed state considered in 
this paper, and there are upper bounds for classical bits shared between parties per particle sent {K defined below, 
not counting the vacuum) in these schemes. 

This paper is organized as follows. In Sec. II we present a B92-type quantum cryptography scheme using the 
superposition of the vacuum and single particle states. We also calculate the number of classical bits transferred per 
particle. In Sec. Ill we extend the arguments to a BB84-type scheme. In Sec. IV possible experimental realizations 
of our schemes using cavity QED and linear optics are presented, and a security analysis is given. Finally, in Sec. V 
we present a concluding discussion. 
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FIG. 1: Schematic of the cavity QED apparatus used in the B92-type quantum cryptography scheme using superpositions of 
the vacuum and the single photon state. See text for detailed explanations. 



II. B92-TYPE SCHEME 



Fig. 1 shows our B92-type quantum cryptography scheme using a cavity QED device. As is well known the B92 
protocol exploits the fact that arbitrary two non-orthogonal states can not be distinguished perfectly. Basically our 
scheme with a superposition of the vacuum and single photon is just the same as the B92 scheme except for the state 
and the measuring device used. For clarification we describe the scheme. 

(i) Alice sends sequences of states randomly chosen between two non-orthogonal states \4>o) and |0i) representing 
logical and 1, respectively; 



I0o> = ao\0)+f3o\l), 
= ai|0)-K/3i|l), 

with normalization \ai\'^ + |/3ip = 1 (i = 0, 1). 

(ii) At a photon arrival time Bob measures a projection operator randomly chosen between Pq and Pi; 

Po = 

Pi = l-|0o)(<^o|. 



(1) 



(2) 



(iii) After a series of measurements Bob publicly announces to Alice in which instances he obtained a positive result. 
This happens only when Alice sends \(j)o) and Bob measures Pq or Alice sends \(pi) and Bob measures Pi. In other 
words, with probability 1/2 the state sent by Alice and the projection operator are correlated. In these cases, applying 
projection Pq (Pi) to \(j)o) {\4>i)), Bob obtains a positive result with a probability ,20j 



P - 



(3) 



Thus, after N trials, the total rif, = pN < N bits of keys are successfully shared, if there have been no eavesdropping 
or errors. 

(iv) To certify the absence of an eavesdropper Alice and Bob sacrifice parts of data to check whether Bob obtained 
positive results on Pq (Pi) measurement or not even in the case that Alice sent \(f>i) (|0o))- 

At this point one can pose an interesting question. How many classical bits can Alice transfer per particle sent to 
Bob in an ideal case without errors or eavesdropping up to the step (iii)? According to the Holcvo's theoremp^ Esf 
asymptotically one cannot encode and retrieve reliably more than one bit of classical information per qubit. Note, 
however, that in this letter we are interested in classical bit information not per qubit but per particle excluding the 
vacuum, so the bit information per particle is not restricted by the Holevo bound. In our schemes the number of 
qubits sent is not equal to the number of particles sent, because the states sent are superpositions of the vacuum and 
single particle states. Let us calculate the ratio K. Since Alice should choose randomly between |(/>o) and |0i), the 
density matrix for a transmission can be written as p = {\4>o){4>o\ + l0i)(0i|)/2. So the average number of particles 
sent to Bob is 



np = N Tr{pn) = ^(|/3oP + lAp) < N 



(4) 



3 



where n is the particle number operator. Then the ratio of bits transferred successfully to the average number of 
particles sent is therefore 

l/?oP + |/3iP ■ 

Without loss of generality, using the Bloch representation [ai^jSi) = {cos{9i),e^^^ sin{6i))^ {i = 0,1) we can rewrite 
K as 

1 - \cos{ea)cos{ei) + sin{eo)sin{e^)e'^\^ 

sin^Oo) + single,) ^' 

^ 1 - {\cosieo)cos{9i)\ - \sinieQ)sin{ei)\f 
si-n?{eo) + siii?{ei) 

where ip = ipi — ipo and the equality of the second line is satisfied when •0 = or tt and cos{9o)cos{9i) is opposite in 
signto sin{eo)sin{0i)e''l'. The upper bound on K achieves value 2 asymptotically when sin{9o) — ±szn(^i) (but 
still nonzero, See Fig. 2). Note that the optimal states are near the vacuum but not the vacuum states. In the case 
that only one of sin{6o) and sin{9i) is (i.e., when one of \(j)o) and |0i) is the vacuum state.), K becomes 1. K = 2 
means that in our QKD scheme Alice and Bob can share secure 2 classical bits of information per single quantum 
particle transfer on the average in the ideal situation of no error or eavesdropping. The physical reason for this bound 
is that the more we send the vacuum (i.e. ~ 0), the smaller Up is, but then it is harder to distinguish \(f>i) from 
\(t>o). One can improve the probability of correct classification into 

p^l-\a*oai+p*ol3i\ (7) 



by optimal positive operator valued measures fPOVM') [26l l27| using ancilla qubits. In this case a similar argument 
leads to 



np^ |/?oP + |/3i| 



g=- = 2 ,r" ,.1° ' ^ (8) 



which also has a maximum value 2 under the same condition stated below Eq. 10. (However, we will not consider a 
specific realization of the POVM measurement in this paper.) On the other hand, for ordinary QKD schemes using 
ordinary particle states K is usually smaller than 1, because there are always discarded data (i.e., nj, < N) to prevent 
Eve from distinguishing Alice's states perfectly, while to represent a qubit one or more particles are required(i.e., 
n-p > N). For example the typical B92 scheme using two non-orthogonal photon polarization states has ni, ~ N/2 
(because the probability to get correct sifted keys is 1/2) and Up = N, hence K = 1/2. In this sense, one can say 
that our B92-type scheme requires a relatively smaller (four times smaller) number of particles to be transferred to 
send a given classical bit information than the typical B92 quantum cryptography schemes. This ratio K is similar 
to the key ratio per energy [isl l2^ but not exactly equal to that, because in QKD schemes usually a sender and a 
receiver consume additional energy to share their references and to communicate publicly. K is more likely a "key 
rate per brightness" which measure how dark the quantum channel is for a fixed information transmission rate. If we 
have a QKD scheme with very big K, we can use the scheme to hide the quantum channel itself from eavesdroppers, 
who will encounter a problem to find out where and when the quantum channel opens. This fact can be especially 
useful for QKD schemes on a moving satellite or free-space systems. The bound for K for our scheme is non-trivial. If 
if = 2 is just the Holevo bound divided by 1/2 (vaguely guessed proportion of particles in the vacuum-single photon 
superposed states), then we should also have maximal K — 2 for the quantum memory or ordinary quantum channel 
but this is not the case (maximal K = oo for these cases). Furthermore the optimal K value for our scheme even 
does not corresponds to the case where the average particle number in the state is 1/2. Meanwhile the fact that one 
can store or send multi-bits information per particle is not so surprising. In fact, it is shown that infinite information 
can be transferred through quantum channel at the cost of infinite entropy [2^. However, what is interesting here is 
that although one can store or send infinite information per particle in the quantum memory or through a quantum 
channel using the vacuum-single particle superposition, there is a upper bound for the key rate per particle using 
QKD schemes with the superposition ( at least for the QKD schemes considered in this paper). 
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FIG. 2: Contour plot of the upper bound on the K values (Kmax) as a function of sin[6o) and sin(6\). Gray level represents 
the value from black(O) to white(2). 



III. BB84-TYPE SCHEME 



Compared to the B92 scheme, the BB84 scheme is known to be more robust against the state discrimination 
attack 30] . It is straightforward to extend our consideration to the BB84-type scheme with superposed states of 
the vacuum and single particles. As in the typical BB84 scheme, Alice sends one of four states from two classes 
{|0o): and {|0o) to Bob where (0ol0i) = = (0o|0i) and {i = 0, 1) are not orthogonal to Then, 

Bob measures one of four projection operators Pj = or P/ = \(f>'j) {(t>^\. After basis reconciliation with Alice 

via a public channel Bob would get the classical bit information with probability 1/2, hence nf, = The density 

matrix of Ahce's particle is p = (|0o)(0o| + + Wo)Wo \ + /4- Therefore, the ratio of bits shared to 

the number of particles sent in this scheme is 



2(|/3oP + |/3iP + |/3^|2 + |/3;|2)' 

where \<j)i) = Q!i|0) + and = a,-|0) + The orthogonality condition ((/)o|0i) = = (0q|0'j) implies 

|/3oP + = 1 = l/^oP + l/^iP' K — 1 which is twice the value of K for BB84 schemes with ordinary particles, 
because for the ordinary BB84 protocol rif, = N 12 and rip = N . 



IV. APPARATUS AND SECURITY 



We may now proceed to the description of the apparatuses for our schemes shown in Fig. 1 for the B92-type 
scheme and in Fig. 3 for the BB84-type scheme. The setups consist of Alice's photon source(S) for generation of 
the superposition of the vacuum and single particle states, and Bob's projective measurement device using either 
cavity QED (Fig. 1) or linear optics (Fig. 3) which are considered by many authorslHmili. In principle the 
cavity QED devices and the linear optics devices can be used both for the B92 or the BB84 scheme. The detectors 
are essentially the same detectors we considered in our previous work|l]|. so we will just briefly review here. Let 
us first consider Fig. 1. By utilizing the parametric down conversion or coherent light, the source(S) generates 
00 or 01 on Alice's demand. Assuming that at time i = a ground state atom \g) is injected into the cavity C, 
the total cavity-atom state is then |'0(O)) = \(t>i)\g). The interaction between atoms and photons in the cavity 
C are described by the Jaynes-Cummings Hamiltonian. With this Hamiltonian and by choosing interaction time 
appropriately one can transfer the information of photon states \4>i) to that of the atoms (See the references for 
details). Then the projective measurement on the photon state ajO) can be possible by adjusting appropriately 

the field in the Ramsey zones (i?) such that the state undergoes a unitary evolution to the state which registers 
a click in the state-selective ionization detector So this setup performs ultimately deterministic (i.e.. 
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with probability 1 for ideal cases) projection on \B) = a\0) + f3\l). Let us find \B) such that Pq in Eq. ^ can be 
written as \B){B\. It should satisfies {B\(f>i) = 0, because Po\(j)i) = 0. In other words, to measure Pq Bob should 
set the fields in the Ramsey zone so that the input photon state with a = f3l and /3 — — a| (i.e. orthogonal to 
|0i)) corresponds to the click on detector D. Similarly Bob can measure Pi by performing projection on (3q\0) — agll). 
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FIG. 3; Schematic of the linear optics apparatus used in the BB84-type quantum cryptography scheme using the superpositions 
of the vacuum and the single particle state. See text for detailed explanations. 



On the other hand, the projective measurement for the BB84-type scheme using linear optics shown in Fig. |21is 
non-deterministic in a sense that the measurement succeeds only probabilistically. This setup is a modification of the 
setup proposed in ref. . The beam splitter BS performs the mode transformation 



a' \ _ f VR VT^. \ f a 
b' -[ -x/T— R [b 



(10) 



where R is the reflectivity of the beam splitter. In second quantized notation, the general input state shown in Fig. 
13 can be written as 



ip = (7 + (5 at)(a + /? 6^)|0) 



(11) 



with normalization |ap + = 1. Here, (7 + <5 a^)|0) is a known probe state, while a\0) + (3\1) is an unknown input 
state to be measured. By replacing a and b in Eq. Hll|) with a' and b' using Eq. H10() . we obtain the output state 
■0 = [a7 + ^{a''''^ - b'^^) + V^/Sja'^lO), if we set R = 1/2 and aS = (ij. Therefore, by noting that the detector 
Da detects single photon and Db detects none, Bob can perform projective measurement on the superposition state 
a|0) + with the probability of success 2|/37p < l/2[llj. To detect |1) or |0) state we simply replace the beam 
splitter and check whether the detector Da fires or not. Then, one of four states {|(/>o), \4'i)^ I0o) \4>i)} oi the section 
III sent to Bob by Alice can be measured with this apparatus for the BB84-type scheme. 

Let us now discuss the security of our schemes. Basically our schemes follow the ordinary B92 and the BB84 
schemes except for the states and measuring devices used, so one can simply adopt the well known security proof 
for these ordinary schemesls^ for our schemes also. Another merit of our schemes is that since the superposition of 
the vacuum and one photon is not a photon number eigenstate, our schemes are robust against the photon number 
splitting (PNS) attacksfs^. (The PNS attacks restrict key rates and distance for many practical QKD schemes such 
as typical B92 or BB84 QKD schemes with weak coherent states.) Because, even in the case the eavesdropper (Eve) 
has multiple copies of the state (|(^)®") due to imperfections of the light sources, to do the PNS attack Eve should 
perform the photon number non-demolition measurement, but our schemes use the superposed states of the vacuum 
and single photon which is inevitably destroyed by any photon number measurement. This allows Alice and Bob 
to detect Eve attempting the PNS attack by publicly comparing parts of the qubits sent with the qubits received. 
So our schemes present yet another way for security against the PNS attacks different from the recently proposed 
schemes [sg). 

For our schemes sending the pure vacuum (|0) = |0)) as a qubit has an intrinsic problem that Bob can not distinguish 
the vacuum from channel loss. But fortunately as described above the pure vacuum state is not the optimal state for 
the maximal K value. So there is no reason to use the pure vacuum state as a qubit for our schemes and we can avoid 
this problem by simply not using the pure vacuum state. In a practical sense, it is experimentally interesting but 



6 



challenging to implement the detection of a superposition of the vacuum and single-photon states|23, |37|. Recently, 
there are many related experimental and theoretical works about transferring quantum states using the cavity js^. 

V. DISCUSSION 

In summary, we have proposed the B92 and the BB84-type quantum key distribution schemes using superposed 
states of the vacuum and the single particle state robust against PNS attacks. We showed that in our QKD schemes 
using the vacuum-photon superposition states the information transferred per particle sent is bounded. So far it is 
unclear that this restriction has more profound physical reasons. Therefore proving or disproving the existence of an 
exotic QKD protocol which has a big value of K, that is, a QKD scheme with very faint light might be an interesting 
subject. 
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of Science and Technology of Korea. E. Lee was supported by the Korea Research Foundation ( Grant No. 
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